Children's privacy.
CohortLedger is built for adult operators of schools that serve children. Here is how we treat data about those children under COPPA, FERPA, and state student data privacy laws.
Effective June 8, 2026
Effective date: June 8, 2026. Last reviewed: June 14, 2026.
1. Who this applies to
CohortLedger is intended for use by adult operators (the people running a microschool, learning pod, or homeschool co-op). The schools that use CohortLedger commonly serve children, and many of those children are under 13. This policy explains how CohortLedger treats information about children, with particular attention to:
- The federal Children’s Online Privacy Protection Act(COPPA, 15 U.S.C. § 6501 et seq.) and the FTC’s COPPA Rule (16 CFR Part 312).
- The Family Educational Rights and Privacy Act (FERPA, 20 U.S.C. § 1232g) and its implementing regulations at 34 CFR Part 99.
- State student data privacy laws, including New York Education Law § 2-d, Illinois SOPPA (105 ILCS 85), California SOPIPA (Cal. Bus. & Prof. Code § 22584), Connecticut student data privacy law, and Colorado student data privacy law.
2. Our role under COPPA: school-authorized service provider
Children do not log in to CohortLedger and CohortLedger does not collect personal information directly from any child. The dashboard is used by the adult operator, not by students.
For children under 13 whose records are entered by the school into CohortLedger, the school stands in as the parent’s agent for consent purposes consistent with the FTC’s guidance interpreting 16 CFR § 312.5(b)(1): the COPPA school-authorized operator exception. Under that exception, a school may authorize an online service to collect children’s personal information on the school’s behalf when the data is used solely for the educational purpose authorized by the school. CohortLedger uses the data only for the educational and administrative purposes specified by the school in the Data Processing Addendum and in these policies. Schools using CohortLedger represent that any required parental notification has been provided.
3. Our role under FERPA: school official with legitimate educational interest
Where CohortLedger is used by an educational agency or institution subject to FERPA, CohortLedger acts as a school official with a legitimate educational interest in the relevant student records under 34 CFR § 99.31(a)(1)(i)(B). CohortLedger performs an institutional service or function for which the school would otherwise use its own employees; CohortLedger is under the direct control of the school with respect to the use and maintenance of education records; and CohortLedger is subject to the use and re-disclosure requirements of 34 CFR § 99.33(a) governing personally identifiable information from education records.
4. What information about children we hold
The operator records the minimum information needed to bill, register a child with an ESA program, and meet state attendance and quarterly reporting rules:
- First name, last name, grade level, enrollment date.
- The family the child belongs to and any sibling relationships.
- The state ESA program assigned to the child, if any.
- Quarterly funding amounts and statuses.
- Attendance entries (present, late, excused, absent), per instructional day.
We do not collect or store: child photos, child health records, biometric data, social security numbers, geolocation data, persistent identifiers tied to a child for tracking purposes, or device fingerprints from children. We do not display advertising to children. We do not use any child’s information to build a profile for any purpose other than operating the service for the school.
5. What we never do
- We do not sell child data to anyone.
- We do not share child data with advertising networks.
- We do not use student records to train AI models, ours or any third party’s.
- We do not market to children. The dashboard is for adult operators.
- We do not enable any in-app communication channel that puts a child in direct contact with anyone outside the school.
6. Parental rights and contact
Parents who want to access, correct, or request deletion of information about their child should contact their school directly. The school is the controller of that information under the DPA, is in the best position to verify identity, and is the right party to respond. CohortLedger will support the school in fulfilling verified parent requests, subject to state record-retention rules.
If a parent has a COPPA-specific concern that the school is unable to resolve, or a question about how CohortLedger handles child data, email privacy@cohortledger.com or write to Privacy & Data Protection, Ravencord Inc., 6688 Nolensville Rd, Ste 108 #2225, Brentwood, TN 37027, United States. We target a two-business-day response.
7. Right to file an FTC complaint
Parents who believe their child’s personal information has been collected, used, or disclosed in violation of COPPA may file a complaint with the US Federal Trade Commission at reportfraud.ftc.gov or by mail to: Federal Trade Commission, Consumer Response Center, 600 Pennsylvania Avenue NW, Washington, DC 20580. State attorneys general may also accept COPPA-related complaints from residents of their state.
8. Operator responsibilities
Operators using CohortLedger agree, by virtue of the Terms of Service and the DPA:
- To obtain any required parental notifications or consents under applicable state law before enrolling a child in CohortLedger.
- To respond to parental access, correction, and deletion requests within the school’s reasonable timelines and to relay verified requests to CohortLedger when our support is needed.
- To not upload information about a child that the operator does not have the right to use.
- To not upload child photos, biometric records, or health records into CohortLedger.
9. State student data privacy laws
CohortLedger’s default practices are designed to align with the principles common across US state student data privacy laws: data minimization, purpose limitation, transparency, no sale, no targeted advertising, defined retention, and verified rights handling.
- New York operators must execute the New York Parents Bill of Rights Addendum before transmitting NY student records, per NY Education Law § 2-d.
- Illinois operators are covered by SOPPA-compliant terms in the DPA, including the prohibitions and required notices set out in 105 ILCS 85.
- California operatorsare covered by SOPIPA (Cal. Bus. & Prof. Code § 22584) terms in the DPA.
- Connecticut and Colorado operators can request state-specific addenda by emailing legal@cohortledger.com.
10. Reporting concerns
If you believe a school is misusing CohortLedger to handle child data in a way that violates COPPA, FERPA, or applicable state law, contact privacy@cohortledger.com. We take these reports seriously and will investigate.
